ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-54421
+2 in the same advisory: …54117 …54118
NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • namelessmc nameless
CVE-2025-32389
NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refers to the structure `?param[0]=a¶m[1]=b¶m[2]=c` utilized by PHP, which is parsed by PHP as `$_GET['param']` being of type array. This issue has been patched in version 2.1.4.

NVD description · AI analysis pending
8.6
group max
<1% PoC
  • namelessmc nameless
CVE-2025-22144
+1 in the same advisory: …22142
NamelessMC is a free, easy to use & powerful website software for Minecraft servers.

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromise another users password and take over their account. This issue has been addressed in release version 2.1.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
9.0
group max
<1% PoC
  • namelessmc nameless
CVE-2022-2820
+1 in the same advisory: …2821
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.

Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.

NVD description · AI analysis pending
8.2
group max
<1% PoC
  • namelessmc nameless